Lp3
Medium
- Category
- MCP Least Privilege
- Confidence
- 80% confidence
- Finding
- The skill documentation describes scripts that use network access and environment variables, but the skill does not declare corresponding permissions. This weakens transparency and reviewability, making it easier for users or platforms to underestimate what the skill can access and do at runtime.
